Contains the Concourse pipeline definition for building a line-server container
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

355 lines
8.8 KiB

9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
  1. package main
  2. import (
  3. "bytes"
  4. "encoding/json"
  5. "errors"
  6. "fmt"
  7. "io"
  8. "net/http"
  9. "net/url"
  10. "path"
  11. "path/filepath"
  12. "regexp"
  13. "strconv"
  14. "strings"
  15. "time"
  16. "github.com/dchest/uniuri"
  17. "github.com/zenazn/goji/web"
  18. "gopkg.in/h2non/filetype.v1"
  19. )
  20. var fileBlacklist = map[string]bool{
  21. "favicon.ico": true,
  22. "index.htm": true,
  23. "index.html": true,
  24. "index.php": true,
  25. "robots.txt": true,
  26. "crossdomain.xml": true,
  27. }
  28. // Describes metadata directly from the user request
  29. type UploadRequest struct {
  30. src io.Reader
  31. filename string
  32. expiry time.Duration // Seconds until expiry, 0 = never
  33. randomBarename bool
  34. deletionKey string // Empty string if not defined
  35. }
  36. // Metadata associated with a file as it would actually be stored
  37. type Upload struct {
  38. Filename string // Final filename on disk
  39. Metadata Metadata
  40. }
  41. func uploadPostHandler(c web.C, w http.ResponseWriter, r *http.Request) {
  42. if !strictReferrerCheck(r, getSiteURL(r), []string{"Linx-Delete-Key", "Linx-Expiry", "Linx-Randomize", "X-Requested-With"}) {
  43. badRequestHandler(c, w, r)
  44. return
  45. }
  46. upReq := UploadRequest{}
  47. uploadHeaderProcess(r, &upReq)
  48. contentType := r.Header.Get("Content-Type")
  49. if strings.HasPrefix(contentType, "multipart/form-data") {
  50. file, headers, err := r.FormFile("file")
  51. if err != nil {
  52. oopsHandler(c, w, r, RespHTML, "Could not upload file.")
  53. return
  54. }
  55. defer file.Close()
  56. r.ParseForm()
  57. if r.Form.Get("randomize") == "true" {
  58. upReq.randomBarename = true
  59. }
  60. upReq.expiry = parseExpiry(r.Form.Get("expires"))
  61. upReq.src = file
  62. upReq.filename = headers.Filename
  63. } else {
  64. if r.FormValue("content") == "" {
  65. oopsHandler(c, w, r, RespHTML, "Empty file")
  66. return
  67. }
  68. extension := r.FormValue("extension")
  69. if extension == "" {
  70. extension = "txt"
  71. }
  72. upReq.src = strings.NewReader(r.FormValue("content"))
  73. upReq.expiry = parseExpiry(r.FormValue("expires"))
  74. upReq.filename = r.FormValue("filename") + "." + extension
  75. }
  76. upload, err := processUpload(upReq)
  77. if strings.EqualFold("application/json", r.Header.Get("Accept")) {
  78. if err != nil {
  79. oopsHandler(c, w, r, RespJSON, "Could not upload file: "+err.Error())
  80. return
  81. }
  82. js := generateJSONresponse(upload, r)
  83. w.Header().Set("Content-Type", "application/json; charset=UTF-8")
  84. w.Write(js)
  85. } else {
  86. if err != nil {
  87. oopsHandler(c, w, r, RespHTML, "Could not upload file: "+err.Error())
  88. return
  89. }
  90. http.Redirect(w, r, Config.sitePath+upload.Filename, 303)
  91. }
  92. }
  93. func uploadPutHandler(c web.C, w http.ResponseWriter, r *http.Request) {
  94. upReq := UploadRequest{}
  95. uploadHeaderProcess(r, &upReq)
  96. defer r.Body.Close()
  97. upReq.filename = c.URLParams["name"]
  98. upReq.src = r.Body
  99. upload, err := processUpload(upReq)
  100. if strings.EqualFold("application/json", r.Header.Get("Accept")) {
  101. if err != nil {
  102. oopsHandler(c, w, r, RespJSON, "Could not upload file: "+err.Error())
  103. return
  104. }
  105. js := generateJSONresponse(upload, r)
  106. w.Header().Set("Content-Type", "application/json; charset=UTF-8")
  107. w.Write(js)
  108. } else {
  109. if err != nil {
  110. oopsHandler(c, w, r, RespPLAIN, "Could not upload file: "+err.Error())
  111. return
  112. }
  113. fmt.Fprintf(w, "%s\n", getSiteURL(r)+upload.Filename)
  114. }
  115. }
  116. func uploadRemote(c web.C, w http.ResponseWriter, r *http.Request) {
  117. if Config.remoteAuthFile != "" {
  118. result, err := checkAuth(remoteAuthKeys, r.FormValue("key"))
  119. if err != nil || !result {
  120. unauthorizedHandler(c, w, r)
  121. return
  122. }
  123. }
  124. if r.FormValue("url") == "" {
  125. http.Redirect(w, r, Config.sitePath, 303)
  126. return
  127. }
  128. upReq := UploadRequest{}
  129. grabUrl, _ := url.Parse(r.FormValue("url"))
  130. resp, err := http.Get(grabUrl.String())
  131. if err != nil {
  132. oopsHandler(c, w, r, RespAUTO, "Could not retrieve URL")
  133. return
  134. }
  135. upReq.filename = filepath.Base(grabUrl.Path)
  136. upReq.src = resp.Body
  137. upReq.deletionKey = r.FormValue("deletekey")
  138. upReq.randomBarename = r.FormValue("randomize") == "yes"
  139. upReq.expiry = parseExpiry(r.FormValue("expiry"))
  140. upload, err := processUpload(upReq)
  141. if strings.EqualFold("application/json", r.Header.Get("Accept")) {
  142. if err != nil {
  143. oopsHandler(c, w, r, RespJSON, "Could not upload file: "+err.Error())
  144. return
  145. }
  146. js := generateJSONresponse(upload, r)
  147. w.Header().Set("Content-Type", "application/json; charset=UTF-8")
  148. w.Write(js)
  149. } else {
  150. if err != nil {
  151. oopsHandler(c, w, r, RespHTML, "Could not upload file: "+err.Error())
  152. return
  153. }
  154. http.Redirect(w, r, Config.sitePath+upload.Filename, 303)
  155. }
  156. }
  157. func uploadHeaderProcess(r *http.Request, upReq *UploadRequest) {
  158. if r.Header.Get("Linx-Randomize") == "yes" {
  159. upReq.randomBarename = true
  160. }
  161. upReq.deletionKey = r.Header.Get("Linx-Delete-Key")
  162. // Get seconds until expiry. Non-integer responses never expire.
  163. expStr := r.Header.Get("Linx-Expiry")
  164. upReq.expiry = parseExpiry(expStr)
  165. }
  166. func processUpload(upReq UploadRequest) (upload Upload, err error) {
  167. // Determine the appropriate filename, then write to disk
  168. barename, extension := barePlusExt(upReq.filename)
  169. if upReq.randomBarename || len(barename) == 0 {
  170. barename = generateBarename()
  171. }
  172. var header []byte
  173. if len(extension) == 0 {
  174. // Pull the first 512 bytes off for use in MIME detection
  175. header = make([]byte, 512)
  176. n, _ := upReq.src.Read(header)
  177. if n == 0 {
  178. return upload, errors.New("Empty file")
  179. }
  180. header = header[:n]
  181. // Determine the type of file from header
  182. kind, err := filetype.Match(header)
  183. if err != nil || kind.Extension == "unknown" {
  184. extension = "file"
  185. } else {
  186. extension = kind.Extension
  187. }
  188. }
  189. upload.Filename = strings.Join([]string{barename, extension}, ".")
  190. upload.Filename = strings.Replace(upload.Filename, " ", "", -1)
  191. fileexists, _ := fileBackend.Exists(upload.Filename)
  192. // Check if the delete key matches, in which case overwrite
  193. if fileexists {
  194. metad, merr := metadataRead(upload.Filename)
  195. if merr == nil {
  196. if upReq.deletionKey == metad.DeleteKey {
  197. fileexists = false
  198. }
  199. }
  200. }
  201. for fileexists {
  202. counter, err := strconv.Atoi(string(barename[len(barename)-1]))
  203. if err != nil {
  204. barename = barename + "1"
  205. } else {
  206. barename = barename[:len(barename)-1] + strconv.Itoa(counter+1)
  207. }
  208. upload.Filename = strings.Join([]string{barename, extension}, ".")
  209. fileexists, err = fileBackend.Exists(upload.Filename)
  210. }
  211. if fileBlacklist[strings.ToLower(upload.Filename)] {
  212. return upload, errors.New("Prohibited filename")
  213. }
  214. // Get the rest of the metadata needed for storage
  215. var expiry time.Time
  216. if upReq.expiry == 0 {
  217. expiry = neverExpire
  218. } else {
  219. expiry = time.Now().Add(upReq.expiry)
  220. }
  221. bytes, err := fileBackend.Put(upload.Filename, io.MultiReader(bytes.NewReader(header), upReq.src))
  222. if err != nil {
  223. return upload, err
  224. } else if bytes > Config.maxSize {
  225. fileBackend.Delete(upload.Filename)
  226. return upload, errors.New("File too large")
  227. }
  228. upload.Metadata, err = generateMetadata(upload.Filename, expiry, upReq.deletionKey)
  229. if err != nil {
  230. fileBackend.Delete(upload.Filename)
  231. return
  232. }
  233. err = metadataWrite(upload.Filename, &upload.Metadata)
  234. if err != nil {
  235. fileBackend.Delete(upload.Filename)
  236. return
  237. }
  238. return
  239. }
  240. func generateBarename() string {
  241. return uniuri.NewLenChars(8, []byte("abcdefghijklmnopqrstuvwxyz0123456789"))
  242. }
  243. func generateJSONresponse(upload Upload, r *http.Request) []byte {
  244. js, _ := json.Marshal(map[string]string{
  245. "url": getSiteURL(r) + upload.Filename,
  246. "filename": upload.Filename,
  247. "delete_key": upload.Metadata.DeleteKey,
  248. "expiry": strconv.FormatInt(upload.Metadata.Expiry.Unix(), 10),
  249. "size": strconv.FormatInt(upload.Metadata.Size, 10),
  250. "mimetype": upload.Metadata.Mimetype,
  251. "sha256sum": upload.Metadata.Sha256sum,
  252. })
  253. return js
  254. }
  255. var bareRe = regexp.MustCompile(`[^A-Za-z0-9\-]`)
  256. var extRe = regexp.MustCompile(`[^A-Za-z0-9\-\.]`)
  257. var compressedExts = map[string]bool{
  258. ".bz2": true,
  259. ".gz": true,
  260. ".xz": true,
  261. }
  262. var archiveExts = map[string]bool{
  263. ".tar": true,
  264. }
  265. func barePlusExt(filename string) (barename, extension string) {
  266. filename = strings.TrimSpace(filename)
  267. filename = strings.ToLower(filename)
  268. extension = path.Ext(filename)
  269. barename = filename[:len(filename)-len(extension)]
  270. if compressedExts[extension] {
  271. ext2 := path.Ext(barename)
  272. if archiveExts[ext2] {
  273. barename = barename[:len(barename)-len(ext2)]
  274. extension = ext2 + extension
  275. }
  276. }
  277. extension = extRe.ReplaceAllString(extension, "")
  278. barename = bareRe.ReplaceAllString(barename, "")
  279. extension = strings.Trim(extension, "-.")
  280. barename = strings.Trim(barename, "-")
  281. return
  282. }
  283. func parseExpiry(expStr string) time.Duration {
  284. if expStr == "" {
  285. return time.Duration(Config.maxExpiry) * time.Second
  286. } else {
  287. expiry, err := strconv.ParseUint(expStr, 10, 64)
  288. if err != nil {
  289. return time.Duration(Config.maxExpiry) * time.Second
  290. } else {
  291. if Config.maxExpiry > 0 && (expiry > Config.maxExpiry || expiry == 0) {
  292. expiry = Config.maxExpiry
  293. }
  294. return time.Duration(expiry) * time.Second
  295. }
  296. }
  297. }